LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2008-4933 CVE-2008-4934 CVE-2008-5029
Created:November 24, 2008 Updated:November 4, 2009
Description:

From the Mandriva advisory:

Buffer overflow in the hfsplus_find_cat function in fs/hfsplus/catalog.c in the Linux kernel before 2.6.28-rc1 allows attackers to cause a denial of service (memory corruption or system crash) via an hfsplus filesystem image with an invalid catalog namelength field, related to the hfsplus_cat_build_key_uni function. (CVE-2008-4933)

The hfsplus_block_allocate function in fs/hfsplus/bitmap.c in the Linux kernel before 2.6.28-rc1 does not check a certain return value from the read_mapping_page function before calling kmap, which allows attackers to cause a denial of service (system crash) via a crafted hfsplus filesystem image. (CVE-2008-4934)

The __scm_destroy function in net/core/scm.c in the Linux kernel 2.6.27.4, 2.6.26, and earlier makes indirect recursive calls to itself through calls to the fput function, which allows local users to cause a denial of service (panic) via vectors related to sending an SCM_RIGHTS message through a UNIX domain socket and closing file descriptors. (CVE-2008-5029)

Alerts:
CentOS CESA-2009:1550 2009-11-04
Red Hat RHSA-2009:1550-01 2009-11-03
Red Hat RHSA-2009:0021-01 2009-02-24
Mandriva MDVSA-2008:246 2008-12-29
CentOS CESA-2009:0014 2009-01-15
Red Hat RHSA-2009:0264-01 2009-02-10
SuSE SUSE-SA:2009:008 2009-01-29
Debian DSA-1687-1 2008-12-15
Debian DSA-1681-1 2008-12-04
SuSE SUSE-SA:2008:057 2008-12-04
Ubuntu USN-679-1 2008-11-27
Mandriva MDVSA-2008:234 2008-11-21
Mandriva MDVSA-2009:032 2009-01-30
SuSE SUSE-SA:2009:004 2009-01-21
Red Hat RHSA-2009:0009-02 2009-01-22
Red Hat RHSA-2009:0225-02 2009-01-20
SuSE SUSE-SA:2009:003 2009-01-20
Red Hat RHSA-2009:0014-01 2009-01-14

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds